• No results found

Cloud Computing. What we should be auditing

N/A
N/A
Protected

Academic year: 2021

Share "Cloud Computing. What we should be auditing"

Copied!
51
0
0

Loading.... (view fulltext now)

Full text

(1)

Cloud Computing

(2)
(3)

What is cloud computing?

Model Description What it does Examples

SAAS Software as a service Applications often available through a browser Workday, Salesforce.com

PAAS Platform as a service Platform to allow customer to develop applications Microsoft AZURE

IAAS Infrastructure as a

service

Servers, networks for clients to store data on – replaces your data center

(4)

What is cloud computing?

• Most common uses

 Web hosting

76%

 Email hosting

57%

 Cloud storage and file sharing 48%

(5)
(6)

What does that mean for audit?

Bad news

You don’t know where the

(7)

What does that mean for audit?

Bad news

You don’t know where the

computers are, what is on them or

what they do

(8)

What does that mean for audit?

Bad news

You don’t know where the

computers are, what is on them or

what they do”

Worse news

You aren’t allowed to check them

Worst of all

The top 4 commissioning

departments are IT, Marketing,

Sales and HR

Marketing (45%), Sales (43%) and Human Resources (40%) are the three most common departments funding cloud initiatives outside of IT.

(9)

What does that mean for audit - consequences

If you don’t know where the computers are,

what is on them or what they do…

(10)

What does that mean for audit - consequences

If you aren’t allowed to check them…

(11)

What does that mean for audit - consequences

If the business is using the cloud for “business

reasons”…

(12)

… how do I audit what I used to be able to audit?

Depends on the service

SAAS Application functionality only

PAAS All application based controls

IAAS

All system based controls including

operating systems and databases

• Check contract

• Contact supplier

(13)

… how do I audit what I used to be able to audit?

Clarify what elements you want to review

• Application – Functionality

– Segregation of duties – Field validation

– Logical access controls – Patching and version – Disaster recovery • Operating system

– Logical access controls – Hardening standards – Patching

(14)

… how do I audit what I used to be able to audit?

Clarify what elements you want to review

• Database

– Logical access controls – Hardening standards – Patching and versions – Admin access

• Physical security – Access

(15)
(16)
(17)

… how do I audit what I used to be able to audit?

If we can:

1. Audit the application

2. Get the right to audit in the

contract

3. Persuade the supplier to

allow us to audit

(18)

how do I audit the cloud technology deployed

?

(19)

how do I audit the cloud technology deployed

?

(20)

how do I audit the cloud technology deployed

?

Virtualization

• We are deploying VMware or equivalent

technology so how does it work?

 This is a technical audit…

 …and you may not be allowed to do it.

• And what exactly are we sharing anyway?

 Check Virtualization operating systems are

(21)

how do I audit the cloud technology deployed

?

The cloud has unique features:

1. Virtualization

(22)

how do I audit the cloud technology deployed

?

Infrastructure

• Can your infrastructure take it? • Bandwidth to cloud?

• Network secure?

(23)

how do I audit the cloud technology deployed

?

The cloud has unique features:

1. Virtualization 2. Infrastructure

(24)

how do I audit the cloud technology deployed

?

Authentication • VPNs?

(25)

how do I audit the cloud technology deployed

?

The cloud has unique features:

1. virtualization 2. Infrastructure 3. Authentication

(26)

how do I audit the cloud technology deployed

?

Performance

• Issue management

• We are sharing, so our issues could be lost • How does help desk change?

• System

(27)

how do I audit the cloud technology deployed

?

The cloud has unique features:

1. virtualization 2. Infrastructure 3. Authentication 4. Performance

(28)

how do I audit the cloud technology deployed

?

Legal

• Data protection • Jurisdiction

 Where is the data exactly? • Encryption

 Where is it encrypted – at rest, in transit?  Backups?

• Data transferability – can I move my data • Legal and Electronic Discovery

 Can we fulfil legal requirements? • Contract

(29)

how do I audit the cloud technology deployed

?

The cloud has unique features:

1. virtualization 2. Infrastructure 3. Authentication 4. Performance 5. Legal

(30)
(31)

how do I audit the business benefits

?

(32)

how do I audit the business benefits

?

Why audit the benefits?

(33)

how do I audit the business benefits

?

Why audit the benefits?

Benefits claimed %

Simplified internal operations 37

Better delivery of internal resources 33

New ways for employees to work 31

Faster rollout of new business initiatives 23

(34)

how do I audit the business benefits

?

Why audit the benefits?

Benefits not claimed %

Simplified internal operations 63

Better delivery of internal resources 67

New ways for employees to work 69

Faster rollout of new business initiatives 77

(35)

how do I audit the business benefits

?

What does the business say the benefits are?

1. Value for money from reduced costs / Capex 2. Implementation speed

 Agility leads to being able to do things like enter new markets, improved productivity and improved responsiveness to

customers

3. Replacing legacy systems so improved capability 4. Enabling business continuity

5. Improved customer support

 Focussed on core business

6. Flexibility and scalability

 Easily deploy your application around the world

(36)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

(37)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

(38)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

Implementation speed Don’t need IT interfering

(39)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

Implementation speed Don’t need IT interfering

Replacing legacy systems Gets rid of old stuff

(40)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

Implementation speed Don’t need IT interfering

Replacing legacy systems Gets rid of old stuff

Enabling business continuity No need for this now

(41)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

Implementation speed Don’t need IT interfering

Replacing legacy systems Gets rid of old stuff

Enabling business continuity No need for this now

Improved customer support Gets rid of systems we don’t like dealing with.

(42)

how do I audit the business benefits

?

What does the business REALLY THINK the benefits are?

Value for money Cheap

Implementation speed Don’t need IT interfering

Replacing legacy systems Gets rid of old stuff

Enabling business continuity No need for this now

Improved customer support Gets rid of systems we don’t like dealing with.

Flexibility and scalability We can increase the size of storage without thinking about the cost or even why we are doing it.

(43)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

Value for money What are the true costs

• Licences

• Operating costs • CAPEX

• Training

• Cost savings

(44)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

Implementation speed How long did it take them to

implement?

• Initial project

• Subsequent implementations • Change requests

(45)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

(46)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

Enabling BC Did they set up new business continuity plans?

Can they cope with:

 DDoS

(47)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

(48)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

Flexibility/ Scalability What have they changed?

 Integration and interfaces  Up-scaling costs

 Flexibility usage

(49)

how do I audit the business benefits

?

How to audit the benefits and stay relevant

Innovation What innovation?

 Fundamental changes to processes  Functionality

(50)

In Summary

1. Focus on why you adopted the cloud

2. Understand key management concerns

3. Emphasis is on security, ROI and delivery against contract

4. Don’t rely on certification

5. Alarm bells

 4th party cloud solutions

 Rogue departments

(51)

The Speaker

Robert Findlay

Global Head of IT Audit Glanbia plc.

References

Related documents

Regardless of the class, family, and boardroom connections that enabled their rise, and regardless of the sweat and suffering of the countless workers whose surplus

Most urban environments are developing haphazardly, due to poor performance by the government and the planning authorities (Planning authorities) burdened with the responsibilities

electronic discovery (the Electronic Discovery Reference Model 2 ), and broad assessments of the economic scale of the market (the Socha-Gelbmann Survey 3 ) have developed

This was calculated by the cost differential between the length of the transfer and the start of care in the subsequent designated place of care (admission area, labour ward,

The Safety-I elements addressed in this study included specific potential errors and error producing conditions related to the discharge process that may result in adverse

Kadar air biji kakao kering dan kelembaban udara tempat penyimpanan merupakan faktor yang penting dalam penyimpanan bahan pertanian.. Masalah teknis yang dihadapi dalam

Frederick Cafasso, Chairman July 8, 2020 July 15, 2020 - LEGAL NOTICE - CITY OF EVERETT PLANNING BOARD 484 BROADWAY EVERETT, MA 02149 PUBLIC HEARING NOTICE.. Hearing on the

20.30 Dinner in a restaurant offering typical southern cuisine & goodbye drink.